Tell HN: Namecheap gave my account to an unverified third party
Points and comments are a snapshot, not live.
Namecheap gave a customer's account to an unverified third party who just asked nicely on a phone call.
A 13-year Namecheap customer helped an old college club by paying for a .com domain registered in his name. During a leadership transition, the incoming club lead initiated a password reset using the domain name. The customer filed a support ticket saying he did not initiate it; Namecheap called to verify him, then sent canned tips. The persistent club lead called Namecheap support and convinced them the domain belonged to his club. With no further verification, Namecheap changed the customer's password and account email. The customer had domain privacy enabled and 2FA enabled. The incident was resolved only after someone told the club lead who the customer was, and they connected directly. The customer has moved critical domains elsewhere.
What commenters are saying
Multiple commenters report similar or worsening experiences with Namecheap. One was locked out after receiving a 24-hour ultimatum to update profile information. Another moved to Porkbun after noticing price hikes and poor practices, noting Namecheap was recently bought by private equity. Several recommend Cloudflare (registration at cost) and NearlyFreeSpeech as alternatives. Two commenters note this resembles SIM swap attacks. One asks whether domain privacy or 2FA were enabled; the thread's author confirms both were, but password reset bypasses 2FA, and a reset can be initiated using just the domain name.